Feds like risky data cloud as alternative to their creaky computer systems

The federal government is willing to store data in the internet cloud as an alternative to its own aging computers

The federal government is willing to accept the privacy and security risks of storing data in the internet cloud as an alternative to its own aging computers that are “at risk of breaking down,” says an internal policy paper.

The federal paper on “data sovereignty,” obtained through the Access to Information Act, fleshes out the government’s plan to embrace the cloud as a solution to its file management woes.

Privately run cloud companies provide customers, such as federal departments, with virtual computer services — from email systems to vast storage capacity — using software, servers and other hardware hosted on the company’s premises.

The government sees the cloud as a way to meet the needs of Canadians in an era of increasing demand for online services.

However, the paper says, ”a number of concerns” related to data control, protection and privacy have been raised within the government, including:

  • — Storage of sensitive information — designated “Protected B” or higher — outside the country, creating a risk that access might be restricted or denied due to a contractual dispute with a company or a disagreement with the host government;
  • — Handoff of certain security responsibilities to the cloud service provider;
  • — The possibility that courts could compel foreign-owned cloud service providers to turn over Canadian data to their governments.

Many countries, including Canada, have laws allowing them to subpoena or obtain a warrant for information from private organizations to support legal investigations, the paper notes.

The U.S. Patriot Act, passed following the 2001 terrorist attacks in New York and Washington, gave the Federal Bureau of Investigation broader access to records held by firms in the United States, including data on Canadians.

In addition, there are long-standing information-sharing agreements and a legal assistance process between security and law-enforcement agencies in both countries — “the most likely vehicles for obtaining access to information held in Canada,” the policy paper says.

Canada’s government has legal obligations to protect personal data and highly sensitive information related to national security, cabinet discussions, military affairs and legal matters.

Related: Liberal elections bill aimed at tighter rules on spending, fake news, privacy

As a result, Treasury Board has drafted a policy declaring all Protected B, Protected C and classified electronic federal data must be stored in a government-approved computing facility located in Canada or within the premises of a department abroad, such as a diplomatic mission, the paper says.

Canada also plans to limit the kinds of files that can be stored in the cloud and to use encryption to shield sensitive data from prying eyes.

There are risks associated with both moving to the “alternative service delivery model” of the cloud and sticking with the government’s aging computer systems, says Alex Benay, the federal chief information officer, in an October memo to the Treasury Board secretary accompanying the paper.

“Ultimately it becomes a risk trade-off discussion, exchanging existing risks for data sovereignty risks (that can be mitigated to some extent).”

Among the current difficulties is the fact the government’s “aging and mission-critical (information technology) infrastructure are at risk of breaking down and must be renewed,” the paper says. Transforming these systems is “proceeding slower than anticipated,” in part due to the challenges and complexities of consolidating 43 departments.

In the same vein, departments have experienced problems with fixing weaknesses promptly, leaving the government “exposed to cyberthreats,” the paper says. In contrast, cloud service providers have significant budgets to “maintain, patch and secure” their systems.

Finally, the government wants to follow the global trend of providing better digital services for citizens, but demand for computing capabilities and storage space “exceeds the supply available,” the paper acknowledges.

“Cloud first” policies have already been adopted by Australia, Britain, New Zealand and the United States, Canada’s Five Eyes allies.

The U.S. has served notice it wants an end to measures that restrict cross-border data flows, or require the use or installation of local computing facilities. It is among the American goals for ongoing NAFTA renegotiation, posing a possible headache for Canada’s cloud-computing plans.

Related: G7 warned of Russian threats to western democracy

Related: Federal government needs help tackling cyberthreats, internal report warns

Jim Bronskill , The Canadian Press

Like us on Facebook and follow us on Twitter.

Just Posted

Spike in Jaffray bear calls cause for concern

In 2018 there were 38 calls about bears spotted in the Jaffray area, compared to one call in 2017.

Snow on the way for Elk Valley

Winter weather advisory issued for East Kootenay with up to 15cm of snow expected over the next week

Snow removal still an issue for mobility challenged in Fernie

Disability advocate sees little improvement in sidewalk clearing; City promises to review policy

Sparwood trails community growing

Sparwood Trails Alliance grows trail network, membership; hosting fatbike event February 2

Huge demand for youth funding in the Elk Valley

Emily Brydon Youth Foundation overwhelmed by 2018/19 winter applications from local youth

B.C. opioid crisis to get same world-renowned treatment approach as HIV/AIDS

A program that focuses on treatment as prevention will roll out Jan. 17

B.C. government extends coastal log export rules for six months

Premier John Horgan talks forest policy at loggers’ convention

B.C. pair accused of ‘honour-killing’ in India to be extradited within days

Malkit Kaur Sidhu and Surjit Singh Badesha are accused of conspiracy to commit murder

OPINION: Jaffray bear meeting good first step, but not enough

A large number of individuals attended the grizzly bear meeting in Jaffray… Continue reading

Netflix rejects request to remove Lac-Megantic images from ‘Bird Box’

At least two shows on Netflix’s Canadian platform briefly use actual footage of the 2013 tragedy

FOCUS: Canada’s revamped impaired driving law brews ‘potential for injustice’

There must be ‘trigger’ for cops to come knocking, Surrey MP says

Barack Obama to speak at Vancouver event

Former U.S. president will speak with board of trade in March

Former welfare clients still owed money, B.C. Ombudsperson says

Investigation found 2,600 people docked illegally for earning income

Prince George could get province’s second BC Cannabis Store

The first brick-and-mortar government retail location opened in Kamloops on Oct. 17

Most Read